Report vulnerabilities through GitHub private vulnerability reporting or the organization security contact. Do not disclose exploit details publicly before maintainers confirm impact and a remediation path.
This repository handles reusable logging packages, redaction behavior, tracing context propagation, transports, and npm release credentials through CI. Security-sensitive changes require relevant package tests, redaction/tracing coverage when affected, and package registry readback after any future npm release.